I post my thoughts and comments about tools, utilities, equipment I am testing and processes. I mainly use this because I can post from my phone. Please enjoy.
Weblog
Tumblr Weblog
In an effort to be able to weblog from my iPhone I am trying to embed Tumblr Weblog tools in my site for this purpose. This is a live log coming from that effort and being shown in my site.
Keep an eye here for future changes!
Thanks…. Scott A. Moulton
Defragging the content inside the MFT!
Today I saw something I thought looked very interesting. Since I do data recovery and forensics and often look at and mess with the MFT. In the past there have been several ways to defrag the location that the MFT was at, but I do not recall ever seeing the ability to defrag the contents of the MFT itself. I received an email about the new product that does just that. I am currently testing this process and can tell you it looks very interesting to see and play with the possibility of defragging these files. I will post my results after I completely test. Take a look at this info yourself and let me know what you think.
A Defragmentation World-First…
http://www.disktrix.com/udboottime.htm

Set your options in this extremely powerful interface where you can adjust and manipulate EVERYTHING relating to your system and metafiles….. then reboot and watch UltimateDefrag do its thing as it defrags and optimizes placement of your system files. No other software product in the world can do this!
The UltimateDefrag 2008 boot time/system file defrag module is a world first in what it enables you to be able to do when it comes to defragging and moving system files to areas on your drive…
Michigan to require CISSP for Computer Forensic Private Investigator License!
Posted and written for SANS Forensics BLOG:
http://sansforensics.wordpress.com/2008/12/05/michigan-requires-cissp-for-private-investigators-license/
I am pleased to have Scott Moulton as a guest Blogger today regarding some new legislation released from Michigan dealing with Computer Forensics and Private Investigation Licensing. –Rob Lee (SANS Institute - forensics.sans.org)
Many of you might know of my involvement in licensing issues for examiners or have seen the “Forensics is for Private Investigators ONLY” speech by Scott Moulton at Defcon 16 earlier this year or have been listening to Dave Kleinman on Brighttalk speaking on the issue. http://www.brighttalk.com/webcasts/1809/attend
The primary issue is that many states are passing laws requiring forensics examiners become private investigators. Now it seems that the state of Michigan now wants you to also have a CISSP to do computer forensics.
Back in May the state of Michigan passed a law making it a felony to practice computer forensics without a PI License that went into effect immediately on May 28th with no grandfather clauses of any kind. Friends of mine that were working on cases had to shut down their shops overnight and…
Why Spinrite is not on my
Data Recovery Software List.
Spinrite is not data recovery software.
I get many questions about why I left off Spinrite on my recommendations of recovery software. I specifically leave off Spinrite because under the strictest terms it is not data recovery software. Almost every single data recovery package knows, and will warn you not to write the data back to the original source drive. Data Recovery/Forensics software almost always recover from a source to a destination. Spinrite does not do that, it refreshes the surface and controls reads to get the maximum amount of data from the sectors and then puts it back down on the same drive.
I think it does quite a few things very well and it does an excellent job at reporting and reading the SMART info and refreshing the surface of the hard drive. However, I would like to first try to get the data from the drive before scanning it and trying to rebuild sectors. There are many reasons for this, but the most important one being that the drive can die in the process of running Spinrite. It is possible to do more damage to the drive by doing excessive read and writes. There are times that you only get once good chance at data and if you use a tool that just goes in…
Vista Problems doing Data Recovery
Round One Testing Vista for Data Recoveries:
I am testing Vista with some of my recoveries and I have found some major problems mounting and using big hard drives in Vista.
For example, I have a 750gig NTFS formatted drive with several thousand small files on it. XP sees it just fine and no problems. However when plugged in Vista it first pauses for a long time and looks like it is trying to count files for that pretty display for free space, however it fails and errors out and shows the hard drive as RAW. It is not raw, and many XP machines have zero problems with it at all. I have also tested in several other configurations and Vista continues to have a problem with the drive.
Second example, I have a 1.5 Terabyte drive with several thousand files formatted as Fat32. Vista does eventually find the drive and mount it, slowly, then displays the count of files correctly and the size. I highlighted and deleted 950 gigs and Vista goes chugging away for 4 days. Yes 4 days to delete 10 folders with 950 gigs. Something I do in XP very quickly.
Third problem, when you open a folder and copy files, even with advanced on, it never tells you what files are being copied. If you are copying…
Simplified: How Raid Arrays Work!
A server enables businesses to share hard drives and resources, and makes central backup a breeze. But having a server without the right equipment will NOT keep your data safe when you need it.

A single person using a computer, if doing backups correctly, would be able to limit their loss in the event of a disaster. However, 10 people using the same hard drive is exponentially a greater loss in the event of a hard drive crash. Ten people working 1 hour, is 10 man hours of work. At 5 pm, if that hard drive crashes it could cost thousands of dollars in lost work and time! How much would 80 man hours of non-productivity cost your business?
Now imagine you could push an On-Hold button the second before the hard drive fails. You could then replace the bad drive before any damage occurs. That is the purpose of a Raid 5 Array.
In case of a failure, a Raid 5 Array protects the server from “down time.” It will allow for a drive to fail and your system to continue running without the result of lost data. Raid 5 does this by storing parity data on all the hard drives. Parity is a formula that calculates error correction data. By…
Google Whitepaper on Disk Failures
http://labs.google.com/papers/disk_failures.pdf
Well after reading the Google study, I have to question the containment of the drives or the way temperature was measured. I have to say that I am 100% convinced that temperature does indeed affect hard drives. The question at this point is how and when.
I have had hard drives in with obvious heat damage, arms and heads deformed due to heat. I have chips that are burnt and physical damage to the platters caused by heat. I know temperature does greatly affect recovery as well. I think this requires more review and that there may be something wrong with the way the temperature is collected. It appears they were using SMART to collect that data. What if there is something so wrong with SMART that it is bad data? That is indicated by the fact they knew in their report that some data reported by the devices was false, but then they still use SMART to gather that data? I would question that!
On the other items, I certainly know that SMART is worthless, and I am not even sure the items it is tracking have correct data. In addition my understanding is that occasionally the SMART data is cleared just because there is only so much space…
A One Touch can Save Your Life and Business!
Most small businesses start out using a single computer or a laptop as their main computer. Many business owners in their first 2 years do not backup at all. They start backing up after their first major catastrophe.
How do you know when your hard drive is going to crash? Most technicians say it is unpredictable. It could be a month, or it could happen tomorrow. I know EXACTLY when a hard drive will crash: The night before the most important meeting of your life. Just in time for you to have a sleepless night
worrying so you won’t be at your best the next day.
If you depend on your data, you should be backing up often. Just one day’s lost data can result in missed business opportunities, lost valuable contracts, pictures, and email. In addition to the lost data, to rub salt in the wound, you will have to pay for data recovery and a hard drive or media to get you back up and running.
Most people do not backup because it is time consuming, hard to remember, or they are not sure how or what to backup. To save yourself the hassle you should consider a One Touch device. Once setup, you can come back to the office, connect the device and push the blue button. You won’t have to tell…
Do You Know Where Your Data Is?
Imagine all your data gone as of right this second! That’s what a hard drive crash feels like. Could your business survive it? What if your hard drive looked like this one? > Would you survive it? Will you lose customers when they find out how you failed to protect their data they trusted you with? Most small businesses start out using a single computer or a laptop as their main computer. Many are not doing a backup of any kind. They start backing up after their first major catastrophe. Notebooks especially have a very sensitive hard drives are the highest rate of failure. If you depend on your data, you should be backing up often. Just one day’s lost data can result in missed business opportunities, lost valuable contracts, pictures, and email. In addition to the lost data, to rub salt in the wound, you will have to pay for data recovery and a hard drive or media to get you back up and running. People don’t backup because it is time consuming, hard to remember, or they are not sure how or what to backup. To save yourself the hassle you should consider a One Touch device. Once setup, you can come back to the office, connect the device and push the blue button. It is very quick… |
